61 Practice Questions & Answers
You need to configure Azure Virtual Desktop to use Azure AD Join for session hosts. Which requirement must be met before implementing Azure AD Join?
-
A
All users must have Azure AD Premium P1 licenses assigned
-
B
Network connectivity to Azure AD endpoints must be established
-
C
The session hosts must be running Windows 10 Enterprise multi-session or Windows 11 Enterprise multi-session
✓ Correct
-
D
A hybrid identity solution must be configured in the on-premises environment
Explanation
Azure AD Join for AVD session hosts requires Windows 10 or Windows 11 Enterprise multi-session operating systems. While Azure AD connectivity is needed, the OS version is the primary prerequisite.
When implementing Azure Virtual Desktop, you configure conditional access policies. What happens when a user's device fails to meet the conditional access requirements during sign-in?
-
A
The sign-in request is blocked or requires additional verification methods
✓ Correct
-
B
The session is established but limited to read-only access
-
C
The device is automatically enrolled in Intune for compliance remediation
-
D
The user is automatically granted access with a warning notification
Explanation
Conditional access policies enforce device and user requirements at sign-in time. Failure to meet policy conditions results in access denial or requirement for additional verification such as MFA.
You are configuring FSLogix profile containers for Azure Virtual Desktop. Which storage solution is recommended for optimal performance in a multi-user environment?
-
A
Azure Files premium SMB shares with high IOPS allocation
✓ Correct
-
B
Managed disks attached to the domain controller
-
C
Azure Table Storage with read-access geo-redundancy
-
D
Azure Blob Storage with standard tier
Explanation
Azure Files premium SMB shares are optimized for FSLogix deployments, providing the necessary IOPS and throughput for multiple concurrent user profile loads in enterprise environments.
During Azure Virtual Desktop deployment, you need to ensure session hosts can authenticate against your on-premises Active Directory. Which hybrid identity approach would you implement?
-
A
Implement Azure AD Connect to synchronize identities and enable seamless sign-on
✓ Correct
-
B
Use Azure AD B2B to invite on-premises users as external identities
-
C
Configure Azure AD Application Proxy for pass-through authentication
-
D
Deploy Azure AD Domain Services as a managed domain replacement
Explanation
Azure AD Connect synchronizes on-premises Active Directory identities to Azure AD, enabling users to authenticate using their domain credentials in Azure Virtual Desktop environments.
You are implementing Azure Virtual Desktop with pooled host pools. Users report inconsistent application availability across sessions. What is the most likely cause?
-
A
Network security groups are blocking RDP traffic between session hosts
-
B
Applications are installed on individual session hosts rather than on all hosts uniformly
✓ Correct
-
C
The host pool load balancing algorithm is incorrectly configured
-
D
The Azure Storage account for FSLogix has insufficient redundancy
Explanation
In pooled host pools, inconsistent application availability typically results from non-standardized application deployment across session hosts. All hosts in a pooled environment should have identical application configurations.
What is the primary advantage of using a personal host pool instead of a pooled host pool in Azure Virtual Desktop?
-
A
Personal host pools eliminate the need for FSLogix profile management entirely
-
B
Personal host pools automatically scale based on user demand without administrator intervention
-
C
Each user receives a dedicated session host, enabling persistent user state and application customization
✓ Correct
-
D
Personal host pools require fewer virtual machines to support the same number of users
Explanation
Personal host pools assign dedicated session hosts to individual users, maintaining persistent application and system state between sessions, which is beneficial for specialized workloads requiring customization.
You configure diagnostics for Azure Virtual Desktop to troubleshoot connection issues. Which diagnostic data helps identify authentication failures during user sign-in?
-
A
Connection diagnostic logs from the AVD Diagnostics workspace in Log Analytics
✓ Correct
-
B
Windows Event Viewer application logs on the domain controller
-
C
Network latency measurements between client and session host
-
D
Session host performance counters and CPU utilization metrics
Explanation
AVD Diagnostics in Log Analytics provides detailed connection logs including authentication events, allowing administrators to trace sign-in failures and session establishment issues.
When deploying Azure Virtual Desktop in a highly regulated industry, you must ensure all user sessions are encrypted. Which encryption method is applied by default to AVD connections?
-
A
Hardware-based encryption on the session host GPU
-
B
SSL/TLS encryption for the RDP protocol communication channel
✓ Correct
-
C
AES-256 encryption at the Azure storage layer only
-
D
User-level encryption managed through Group Policy Objects
Explanation
Azure Virtual Desktop uses SSL/TLS encryption by default to secure RDP protocol communications between clients and session hosts, protecting transmitted data from interception.
You implement autoscale for your Azure Virtual Desktop host pool to manage costs. During off-peak hours, a session host is deallocated. Which impact occurs to active user sessions on that host?
-
A
The host remains active until all user sessions disconnect naturally
✓ Correct
-
B
Users are gracefully disconnected with an option to reconnect to another session host
-
C
Active sessions are migrated transparently to other running hosts
-
D
Sessions are immediately terminated without notification
Explanation
Azure Virtual Desktop autoscale respects active user sessions and will not deallocate a host that has connected users. The host remains active until sessions naturally disconnect.
What is the correct procedure for updating session host images in a running Azure Virtual Desktop host pool to minimize user disruption?
-
A
Configure session hosts to automatically snapshot before each update installation
-
B
Use Windows Update for Businesses to push updates automatically across all hosts
-
C
Apply updates directly to all session hosts during maintenance windows
-
D
Create an updated image, update the host pool image reference, then drain existing hosts before deallocation
✓ Correct
Explanation
The recommended approach involves creating a new image with updates, updating the host pool configuration, then using drain mode to prevent new sessions on old hosts before removal.
You configure the Azure Virtual Desktop environment to use RemoteApp applications instead of full desktop sessions. What operational benefit does this provide?
-
A
Users see only specific applications instead of the full desktop, simplifying the user experience and reducing bandwidth consumption
✓ Correct
-
B
RemoteApp automatically scales session hosts based on application demand without configuration
-
C
RemoteApp prevents users from accessing local drives and clipboard functionality
-
D
RemoteApp eliminates the need for FSLogix profile management
Explanation
RemoteApp delivers individual applications to users rather than full desktop sessions, reducing resource consumption, bandwidth usage, and providing a more focused application experience.
During Azure Virtual Desktop deployment, you discover that users cannot access network printers shared on your on-premises network. Which configuration is required to enable printer access?
-
A
Configure RDP device redirection policies and ensure network connectivity to print servers via VPN or ExpressRoute
✓ Correct
-
B
Install printer drivers on each session host and configure print queue forwarding
-
C
Use only cloud-based printing solutions such as Universal Print
-
D
Implement Azure ExpressRoute for dedicated network connectivity to on-premises infrastructure
Explanation
Printer access requires RDP device redirection configuration and network connectivity to on-premises print servers. This can be achieved through VPN, ExpressRoute, or Azure bastion connectivity.
You need to implement multi-factor authentication (MFA) for Azure Virtual Desktop users. At what point in the authentication process is MFA enforced?
-
A
On the session host during Windows logon after RDP connection is established
-
B
During Azure AD sign-in before the RDP connection is initiated
✓ Correct
-
C
After the user establishes an RDP connection to the session host
-
D
Continuously throughout the session at random intervals
Explanation
MFA for Azure Virtual Desktop is enforced at the Azure AD authentication stage before RDP protocol negotiation, using Azure AD Conditional Access policies.
When configuring user assignments for Azure Virtual Desktop application groups, what is the difference between direct assignment and group assignment?
-
A
Direct assignment supports RemoteApp while group assignment supports desktop sessions only
-
B
Direct assignment is faster but group assignment provides better auditability
-
C
Direct assignment requires manual session host configuration while group assignment is fully automated
-
D
Direct assignment assigns individual users while group assignment uses Azure AD or Active Directory groups for scalable user management
✓ Correct
Explanation
Direct assignment targets specific user accounts, while group assignment uses AD groups, enabling scalable and manageable access control as user populations grow.
You are troubleshooting Azure Virtual Desktop client connectivity issues. Users report that connections drop after 15 minutes of inactivity. Which setting should you review?
-
A
Virtual network security group inactivity timeout rules
-
B
Idle session timeout policy in the host pool configuration or Group Policy settings
✓ Correct
-
C
Azure Load Balancer health probe interval settings
-
D
RDP shortpath session timeout configuration on the session host
Explanation
Idle session disconnection is controlled by Group Policy settings or host pool configurations that define timeout thresholds for inactive RDP sessions.
What is the recommended method for deploying Azure Virtual Desktop in a disaster recovery scenario requiring high availability across multiple regions?
-
A
Deploy host pools in a single region with zone-redundancy across availability zones
-
B
Use Azure Backup to replicate session host images across regions automatically
-
C
Create identical host pools in multiple Azure regions and use Azure Traffic Manager for client distribution
✓ Correct
-
D
Configure active-passive host pools with Azure Site Recovery for failover automation
Explanation
Multi-region AVD deployments use Azure Traffic Manager to distribute clients across identical host pools in different regions, providing geographic redundancy and disaster recovery capabilities.
You configure Azure Virtual Desktop to use the RDP Shortpath transport protocol. Which network requirement must be satisfied for Shortpath to function?
-
A
A direct UDP connection path between the client and session host with port 3390 open
✓ Correct
-
B
All traffic must traverse through the Azure gateway for encryption purposes
-
C
Clients must be connected to the same virtual network as session hosts
-
D
Azure ExpressRoute must be configured between the client location and Azure
Explanation
RDP Shortpath requires a direct UDP connection (typically port 3390) between client and session host, bypassing the Azure gateway for lower latency and reduced bandwidth consumption.
When implementing Azure Virtual Desktop with Start VM on Connect functionality, what prerequisite must be met?
-
A
Azure Automation runbooks must be deployed to orchestrate VM startup sequences
-
B
All session hosts must be configured as personal host pools exclusively
-
C
Session hosts must use managed identities and the service principal must have VM contributor rights on host pool resources
✓ Correct
-
D
Session hosts must have the Azure PowerShell module pre-installed
Explanation
Start VM on Connect requires the Azure Virtual Desktop service to have appropriate managed identity permissions to start deallocated VMs when users connect.
You are configuring user profiles in Azure Virtual Desktop and need to choose between FSLogix, Citrix Profile Manager, and OneDrive for Business. Which combination provides the best profile roaming with Windows Search indexing?
-
A
OneDrive for Business alone is sufficient for all profile roaming scenarios
-
B
Citrix Profile Manager alone provides superior Windows Search integration
-
C
FSLogix profile containers exclusively without additional tools
-
D
FSLogix profile containers combined with OneDrive for Business for document sync and Search indexing
✓ Correct
Explanation
FSLogix provides efficient profile management while OneDrive integrates with Windows Search for indexing, creating a comprehensive solution for profile roaming and search functionality.
During Azure Virtual Desktop operations, you observe that certain RemoteApp applications are not appearing for specific users despite correct application group assignments. What should you verify first?
-
A
Confirm that the application group has been published to the correct workspace
-
B
Check that the user's device is running the latest Azure Virtual Desktop client software
-
C
Verify that session hosts have the application installed and that the user has local execute permissions on the session host
✓ Correct
-
D
Ensure the Azure Virtual Desktop Enterprise license is assigned to the user
Explanation
RemoteApp availability depends on application installation on session hosts and appropriate file system permissions. Users cannot access applications that are not installed or for which they lack execution rights.
What is the primary security advantage of using Azure Bastion instead of exposing RDP ports directly to the internet for Azure Virtual Desktop session host management?
-
A
Bastion reduces latency for remote session connections by optimizing network routing
-
B
Bastion eliminates the need for public IP addresses on session hosts and provides centralized access control
✓ Correct
-
C
Bastion automatically encrypts RDP traffic using AES-256 encryption
-
D
Bastion prevents all network attacks by implementing advanced threat detection
Explanation
Azure Bastion provides secure administrative access to session hosts without exposing RDP ports to the internet, eliminating public IP requirements and enabling centralized access logging and control.
You need to implement Azure Virtual Desktop for a scenario requiring persistent desktop customization and application state preservation across sessions. Which host pool type is most appropriate?
-
A
Shared host pool with group-based resource allocation
-
B
Pooled host pool with FSLogix profile containers
-
C
Personal host pool with assigned session hosts per user
✓ Correct
-
D
Validation host pool with experimental feature enablement
Explanation
Personal host pools assign dedicated session hosts to individual users, preserving all desktop customizations, application installations, and system state between sessions.
When configuring Azure Virtual Desktop compliance requirements, you must ensure that session host operating system patches are applied within 30 days of release. Which approach best automates this requirement?
-
A
Configure Windows Update for Business Group Policies targeting specific patch installation deadlines
-
B
Use Azure Update Management to schedule and track patch deployments across host pools with deadline enforcement
✓ Correct
-
C
Enable automatic shutdown policies to force patching during system startup
-
D
Manually install patches on each session host during monthly maintenance windows
Explanation
Azure Update Management provides scheduled patch deployment with deadline enforcement, compliance reporting, and automation across multiple session hosts, meeting regulatory requirements effectively.
You are implementing Azure Virtual Desktop in an environment with strict data residency requirements. Which configuration ensures that user data remains within a specific geographic region?
-
A
All of the above configurations combined
✓ Correct
-
B
Deploy host pools exclusively in the target region and configure FSLogix storage accounts in the same region
-
C
Configure Azure Storage replication to locally redundant storage (LRS) exclusively within the target region
-
D
Use Azure Policy to enforce resource deployment within specified regions and disable geo-redundancy
Explanation
Comprehensive data residency compliance requires deploying resources in the target region, enforcing regional policies, using LRS storage, and disabling cross-region replication features.
During Azure Virtual Desktop troubleshooting, you find that users experience degraded performance when multiple users access resource-intensive applications simultaneously on the same session host. What is the most effective remediation?
-
A
Reduce session host VM size to force users to lighter application workloads
-
B
Increase the session limit on the host pool to allow more concurrent connections
-
C
Implement session host capacity planning by monitoring CPU, memory, and disk usage, then adjusting VM size or distributing users across additional hosts
✓ Correct
-
D
Configure priority-based session initiation to restrict concurrent access
Explanation
Performance issues stem from insufficient resources. Proper capacity planning involves monitoring resource utilization and either increasing host VM specifications or expanding the host pool.
What is the correct process for implementing zero-trust security principles in an Azure Virtual Desktop environment?
-
A
Deploy a traditional perimeter firewall without additional internal security controls
-
B
Use network isolation to completely separate AVD resources from all external connectivity
-
C
Implement conditional access policies, require MFA, validate device compliance, enforce encryption, and apply principle of least privilege access
✓ Correct
-
D
Disable all network security groups and firewall rules to allow unrestricted access
Explanation
Zero-trust in AVD requires multiple security layers: conditional access enforcement, MFA requirements, device compliance validation, encryption, and least-privilege permissions rather than trust-based models.
You need to migrate existing Remote Desktop Services (RDS) deployments to Azure Virtual Desktop. Which component from RDS does NOT have a direct equivalent in Azure Virtual Desktop?
-
A
RDS License Server with per-device CALs for licensing enforcement
✓ Correct
-
B
RDS Connection Broker (equivalent to AVD broker service integrated into platform)
-
C
RDS Session Host (equivalent to AVD session hosts)
-
D
RDS Gateway (partially replaced by RDP Shortpath and Azure Bastion)
Explanation
Azure Virtual Desktop uses subscription-based licensing rather than RDS CALs. The traditional RDS License Server with per-device licensing model has no direct equivalent in AVD.
You need to deploy Azure Virtual Desktop in a new Azure subscription. Which resource must be created first to support AVD infrastructure?
-
A
Application Group
-
B
Host Pool
-
C
Workspace
-
D
Azure Virtual Network
✓ Correct
Explanation
An Azure Virtual Network is a foundational prerequisite for deploying AVD resources, as all VMs and services require network connectivity. Host Pools, Application Groups, and Workspaces are created after networking is established.
You are configuring a pooled host pool with 10 session hosts for a call center environment. Users report connection failures during peak hours. What is the most likely cause?
-
A
Session hosts have reached maximum session capacity
✓ Correct
-
B
Azure Firewall is not configured
-
C
Session host CPU is below 20%
-
D
The workspace name is too long
Explanation
In a pooled host pool, connection failures during peak hours typically indicate that session hosts have reached their maximum session capacity. This is a configuration and load-balancing issue rather than infrastructure problems.
Your organization requires persistent user desktop environments where each user receives the same desktop upon login. Which host pool type should you implement?
-
A
Pooled with breadth-first load balancing
-
B
Pooled with depth-first load balancing
-
C
Personal with automatic assignment
✓ Correct
-
D
Personal with direct assignment
Explanation
Personal host pools with automatic assignment ensure persistent environments where each user is assigned to a specific session host and receives the same desktop experience. Pooled configurations are for shared environments, while direct assignment requires manual user-to-host mapping.
You need to implement FSLogix profile containers for 500 users across multiple session hosts. Which Azure Storage account configuration provides optimal performance?
-
A
Premium FileShare with SMB 3.1.1 protocol and Active Directory authentication
✓ Correct
-
B
Standard LRS with SMB 2.1 protocol
-
C
Standard GRS with NFS protocol
-
D
Blob storage with public endpoints
Explanation
Premium Azure Files with SMB 3.1.1 protocol and Active Directory authentication is the recommended configuration for FSLogix profile containers, providing optimal performance, encryption in transit, and secure identity-based authentication.
A user's FSLogix profile container is locked and preventing login. What is the appropriate troubleshooting step?
-
A
Restart the Azure Storage account
-
B
Delete the VHD file immediately
-
C
Check the Session Host for orphaned sessions and verify storage account connectivity
✓ Correct
-
D
Change the user's password in Active Directory
Explanation
When a profile container is locked, the issue is typically caused by an orphaned session or storage connectivity problem. Checking for active sessions and verifying storage connectivity will identify the root cause without destructive actions.
You are deploying AVD with Microsoft Entra ID (Azure AD) joined session hosts instead of Active Directory domain-joined. What limitation must you consider?
-
A
Entra ID join does not support FSLogix profile containers in standard configuration
✓ Correct
-
B
On-premises users cannot access resources
-
C
Cloud PC features are automatically included
-
D
Multi-factor authentication is mandatory
Explanation
Microsoft Entra ID-joined session hosts have limitations with FSLogix profile containers in standard configurations. Hybrid join or additional configuration through cloud identity solutions may be required for profile management.
Your organization's AVD deployment experiences high latency for users in remote branch offices. What is the most effective optimization?
-
A
Increase the session host VM size
-
B
Disable graphics acceleration
-
C
Deploy session hosts in an Azure region closer to the users
✓ Correct
-
D
Reduce the maximum session limit
Explanation
Geographic proximity between users and session hosts is the primary factor affecting latency in AVD. Deploying session hosts in a closer region or using Azure regional proximity provides the most effective latency reduction.
You need to configure Azure Virtual Desktop to support graphics-intensive CAD applications. Which session host VM type is most appropriate?
-
A
Standard D4s_v3 with software rendering
-
B
NV-series with GPU acceleration and graphics drivers installed
✓ Correct
-
C
B-series for cost savings with burst capability
-
D
A-series with extended memory
Explanation
NV-series VMs provide GPU acceleration necessary for graphics-intensive applications like CAD. These VMs include NVIDIA GPUs and require appropriate graphics drivers for optimal performance.
You are configuring Application Groups for your AVD deployment. A user should only access specific RemoteApp applications, not the full desktop. Which Application Group type should you create?
-
A
Workspace group
-
B
Session group
-
C
RemoteApp Application Group
✓ Correct
-
D
Desktop Application Group
Explanation
RemoteApp Application Groups allow you to publish individual applications rather than full desktop access. This provides granular control over which applications users can access.
Your AVD environment requires SSO (Single Sign-On) for users accessing both AVD and Microsoft 365 applications. Which authentication method should be implemented?
-
A
Local Active Directory with password synchronization
-
B
Network Policy Server
-
C
RADIUS authentication server
-
D
Microsoft Entra ID with seamless SSO or Hybrid Identity with Entra ID Connect
✓ Correct
Explanation
Microsoft Entra ID with seamless SSO or Hybrid Identity configuration enables users to authenticate once and access both AVD and Microsoft 365 resources without re-authentication.
You need to implement a disaster recovery solution for your AVD environment. Session hosts must be able to failover automatically to a secondary Azure region. What is required?
-
A
Deploy a load balancer across regions
-
B
Use Azure Site Recovery to replicate session host VMs and manage failover orchestration
✓ Correct
-
C
Create duplicate host pools in a secondary region with automated backup and restore procedures
-
D
Configure host pools with automatic regional failover built-in
Explanation
Azure Site Recovery provides the infrastructure for replicating session host VMs to a secondary region and managing automated failover when disasters occur, ensuring business continuity for AVD deployments.
You observe that some users experience printer redirection failures in their AVD sessions. What is the first diagnostic step?
-
A
Disable all printer redirection settings
-
B
Verify that the Universal Print connector is configured and the printer is shared to the user
✓ Correct
-
C
Immediately reinstall all printer drivers on session hosts
-
D
Replace the network with a higher bandwidth connection
Explanation
Printer redirection issues are commonly caused by improper Universal Print configuration or insufficient printer sharing permissions. Verifying connector status and printer assignment is the appropriate first diagnostic step.
Your organization has a requirement to audit all user actions within AVD sessions for compliance purposes. Which feature should you implement?
-
A
Azure Activity Log only
-
B
Azure Monitor alerts
-
C
Session Recording with Windows Event Logs
-
D
Azure Virtual Desktop Diagnostics with Log Analytics and Windows Event Log collection for detailed audit trails
✓ Correct
Explanation
AVD Diagnostics integrated with Log Analytics and Windows Event Log collection provides comprehensive audit trails of user actions. This combination enables compliance requirements for detailed session activity tracking.
You are configuring role-based access control (RBAC) for your AVD infrastructure. Which role allows a user to manage host pools but not create new Azure resources?
-
A
Reader
-
B
Desktop Virtualization Contributor
✓ Correct
-
C
Owner
-
D
Virtual Machine Contributor
Explanation
Desktop Virtualization Contributor role grants permissions to manage AVD resources including host pools and application groups, without granting broad Azure resource creation permissions.
Your AVD environment requires users to connect from unmanaged devices. What security measures should be implemented? (Choose the scenario that best addresses this)
-
A
Allow connections only from IP addresses in a whitelist
-
B
Disable conditional access and allow unrestricted connections
-
C
Implement Conditional Access policies requiring MFA and device compliance checks before session access
✓ Correct
-
D
Use only VPN with no additional authentication
Explanation
Conditional Access policies with MFA and device compliance checks provide robust security for unmanaged device connections by enforcing authentication and compliance requirements before allowing AVD access.
You need to distribute Windows updates to 50 session hosts in a pooled host pool without disrupting user sessions. What approach is recommended?
-
A
Disable Windows Update to prevent disruptions
-
B
Apply updates during business hours to all hosts simultaneously
-
C
Use Azure Update Management with scheduled maintenance windows and drain hosts before updates
✓ Correct
-
D
Manually update one host per week
Explanation
Azure Update Management allows scheduling updates during maintenance windows while host draining ensures no new sessions are assigned, allowing existing sessions to complete before updates are applied.
Your organization is migrating from a legacy VDI solution to Azure Virtual Desktop. You need to transfer 200 user profiles. What is the most efficient method?
-
A
Copy profile folders via shared SMB folder
-
B
Use FSLogix migration tools or third-party migration utilities designed for profile container migration
✓ Correct
-
C
Ask users to recreate their profiles manually
-
D
Manually recreate each profile in the new environment
Explanation
FSLogix provides migration tools and third-party utilities enable efficient migration of multiple user profiles to FSLogix profile containers, maintaining profile integrity and reducing downtime.
You are configuring bandwidth optimization for AVD users on low-speed WAN connections. Which setting provides the most effective optimization?
-
A
Enable graphics compression and adjust video codec settings in RDP properties
✓ Correct
-
B
Increase the session timeout to reduce reconnections
-
C
Use only standard displays without multi-monitor support
-
D
Disable all multimedia redirection
Explanation
Graphics compression and optimized video codec settings in RDP properties are the recommended bandwidth optimizations for low-speed connections, balancing visual quality with network efficiency.
A user cannot connect to their AVD session after a session host Windows Update. What is the most likely cause and appropriate fix?
-
A
Session host network interface is misconfigured; check NIC status and network settings
✓ Correct
-
B
The host pool has been removed
-
C
Azure subscription has expired
-
D
The user's profile has been deleted
Explanation
Windows updates can occasionally affect network configuration. Checking the session host's network interface status and verifying network settings should resolve post-update connectivity issues.
You need to implement auto-scaling for your pooled host pool to handle variable user demand. What is the prerequisite configuration?
-
A
Create a scaling plan and configure autoscale settings with metrics-based or schedule-based triggers
✓ Correct
-
B
Host pool must have load balancing enabled
-
C
Deploy additional availability zones
-
D
Manually adjust session host count daily
Explanation
AVD scaling plans enable automatic adjustment of session host capacity based on schedules or performance metrics. This prerequisite configuration allows the system to add or remove hosts based on demand automatically.
Your organization requires split-tunnel VPN configuration for AVD connections to improve performance. What consideration is most critical?
-
A
Ensure security policies permit split tunneling and that Azure Virtual Desktop traffic routes directly while sensitive data routes through VPN
✓ Correct
-
B
Split tunneling is not supported with AVD
-
C
All traffic must be encrypted through the VPN tunnel
-
D
Split tunneling automatically improves all connection types
Explanation
While split tunneling can improve AVD performance by routing AVD traffic directly, security policies must explicitly permit this configuration and sensitive data must still traverse the VPN tunnel securely.
You are troubleshooting why users cannot see RemoteApp applications published to their Application Group. What is the most common cause?
-
A
RemoteApp applications require additional licensing
-
B
The application must be installed on the user's local device first
-
C
Users are not assigned to the Application Group, or the Application Group is not assigned to the Workspace
✓ Correct
-
D
RemoteApp is only available for personal host pools
Explanation
RemoteApp visibility depends on proper assignment chain: users must be assigned to the Application Group, and the Application Group must be assigned to a Workspace for users to see the applications.
Your AVD environment experiences performance degradation during high-concurrent-session periods. Which metric should you monitor to identify resource bottlenecks?
-
A
Only memory utilization
-
B
Only CPU utilization
-
C
CPU, memory, disk I/O, and network utilization alongside user experience metrics in Azure Monitor and diagnostic logs
✓ Correct
-
D
Network bandwidth only
Explanation
Comprehensive performance analysis requires monitoring multiple metrics including CPU, memory, disk I/O, and network utilization along with user experience metrics to identify true bottlenecks in AVD environments.
You need to ensure that AVD users can access on-premises resources securely. Which network connectivity option provides the best performance?
-
A
Internet-based access only
-
B
Dial-up connection to the data center
-
C
Public IP addresses on session hosts
-
D
Azure ExpressRoute or Site-to-Site VPN with Azure Virtual Network and session host integration
✓ Correct
Explanation
Azure ExpressRoute or Site-to-Site VPN provides secure, dedicated connectivity between AVD session hosts and on-premises resources, offering superior performance and reliability compared to internet-based access.
You need to configure RemoteApp publishing in Azure Virtual Desktop. Which component is responsible for managing the RemoteApp application groups and their assignments?
-
A
Application group
✓ Correct
-
B
Azure Virtual Desktop workspace
-
C
Host pool
-
D
Session host virtual machine
Explanation
Application groups are the Azure Virtual Desktop objects that contain collections of RemoteApps or desktops and control which users can access them. They are essential for publishing and managing RemoteApp resources.
What is the primary purpose of configuring Azure Virtual Desktop Diagnostic Settings?
-
A
To control RemoteApp performance optimization
-
B
To manage user identity and access permissions
-
C
To route activity logs and performance metrics to a storage account or Log Analytics workspace for monitoring and troubleshooting
✓ Correct
-
D
To automatically scale session hosts based on load
Explanation
Diagnostic Settings enable you to send Azure Virtual Desktop logs and metrics to specified destinations for analysis, troubleshooting, and compliance tracking.
You are configuring a multi-session Windows 10 host pool with custom image requirements. After creating the custom image, which Azure service should you use to store and manage the image for AVD deployment?
-
A
Azure File Share
-
B
Azure Shared Image Gallery
✓ Correct
-
C
Azure Blob Storage
-
D
Azure Container Registry
Explanation
Azure Shared Image Gallery is the recommended service for storing, managing, and distributing custom VM images for Azure Virtual Desktop deployments, allowing versioning and replication across regions.
Your organization requires that Azure Virtual Desktop users authenticate using multifactor authentication (MFA). Which Azure service integration is required to enforce this requirement during the initial connection?
-
A
Azure Active Directory Conditional Access
✓ Correct
-
B
Azure Firewall
-
C
Azure Policy
-
D
Azure Security Center
Explanation
Azure AD Conditional Access policies are the primary mechanism for enforcing MFA and other authentication requirements for Azure Virtual Desktop users at the Azure AD authentication layer.
You need to monitor session host CPU utilization and automatically remove unhealthy hosts from the load balancer pool in Azure Virtual Desktop. Which feature should you implement?
-
A
Host pool drain mode combined with Azure Automation runbooks
✓ Correct
-
B
Azure Monitor autoscale with custom metrics
-
C
Virtual Desktop infrastructure (VDI) performance tuning
-
D
Application Group health checks
Explanation
Drain mode prevents new sessions from being assigned to a host while allowing existing sessions to complete, and when combined with Azure Automation, can automatically remove unhealthy hosts from service for maintenance or replacement.
When configuring FSLogix profile containers for Azure Virtual Desktop, what is the primary benefit of using Cloud Cache?
-
A
It automatically encrypts all profile data stored in Azure Files
-
B
It enables multi-session profile sharing across multiple session hosts
-
C
It reduces the size of the profile container files on disk
-
D
It provides local caching of profile data while synchronizing with cloud storage, improving performance and resilience to network issues
✓ Correct
Explanation
FSLogix Cloud Cache maintains a local cache of profile data while synchronizing with remote storage, providing improved performance and offline capability if the cloud storage becomes temporarily unavailable.
You are deploying Azure Virtual Desktop and need to ensure that users can access their session hosts from both internal corporate networks and remote locations securely. Which networking solution provides the most appropriate security boundary while maintaining accessibility?
-
A
Azure Private Link for session host access combined with conditional access policies
-
B
Public IP addresses on all session hosts with Windows Firewall rules
-
C
Network Security Groups (NSGs) configured to allow RDP only from corporate IP ranges
-
D
A site-to-site VPN connection to the corporate network and conditional access enforcement
✓ Correct
Explanation
A site-to-site VPN provides secure access for internal users while conditional access policies enforce security requirements for all users, creating a balanced security and accessibility approach.
When implementing Azure Virtual Desktop for a healthcare organization subject to HIPAA compliance, which storage solution is recommended for storing user profiles and application data?
-
A
Azure Files with HIPAA-eligible service and encryption in transit and at rest
✓ Correct
-
B
Azure Data Lake Storage Gen2 with immutable snapshots
-
C
Standard Azure Blob Storage with encryption at rest
-
D
Azure Queue Storage with message encryption
Explanation
Azure Files is a HIPAA-eligible service that provides encryption in transit and at rest, along with audit logging capabilities required for healthcare compliance when used with FSLogix profile containers.
Your organization has deployed an Azure Virtual Desktop environment and wants to minimize licensing costs while maintaining performance. Which licensing model should be evaluated for session hosts running Windows Server operating systems?
-
A
Monthly pay-as-you-go virtual machine pricing without hybrid benefits
-
B
Azure Hybrid Benefit using existing Server licenses
✓ Correct
-
C
Windows Virtual Desktop per-user subscription model with Premium tier
-
D
Reserved Instance commitments for one year
Explanation
Azure Hybrid Benefit allows organizations to use existing Server licenses to reduce the cost of session hosts running Windows Server, providing significant cost savings over standard licensing.
You need to configure Azure Virtual Desktop to support session reconnection after temporary network interruptions. Which Windows Remote Desktop Protocol (RDP) setting controls this behavior on the session host?
-
A
Configure Azure Application Gateway with session affinity rules
-
B
Configure Azure Load Balancer session persistence for RDP traffic
-
C
Enable Azure Traffic Manager health probes for session hosts
-
D
Enable automatic session reconnection via Group Policy or registry settings on the host pool's session hosts
✓ Correct
Explanation
RDP's automatic session reconnection is controlled through session host Group Policy settings (Computer Configuration > Policies > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Connections), allowing users to reconnect to disconnected sessions automatically.